benmmurphy (@benmmurphy) 's Twitter Profile
benmmurphy

@benmmurphy

Security Researcher (23EE18E2/7B8B082223EE18E2)

ID: 17311483

calendar_today11-11-2008 15:20:42

1,1K Tweet

699 Followers

220 Following

benmmurphy (@benmmurphy) 's Twitter Profile Photo

TIL: Phoenix will kill your request PIDs when a client closes the TCP connection. it’s like the user has the option to pull the power from your server whenever they choose. I’m sure there won’t be any security issues related to this. #elixir

benmmurphy (@benmmurphy) 's Twitter Profile Photo

Remember 2^5 . 100 maximum fine applies if you fail to wear a mask on public transport. The same law was in effect when it was 2^0 . 100 minimum but now the sign is red.

benmmurphy (@benmmurphy) 's Twitter Profile Photo

OTP-16765 -> If you were using {session_tickets, auto} with TLS 1.3 and connecting to server A and B then server B could MITM traffic going to server A. (erlang.org/doc/apps/ssl/n…)

benmmurphy (@benmmurphy) 's Twitter Profile Photo

Anyone else get an email purporting to be from Maryland State Board with passing SPF and DKIM but DKIM is from marylandstateboard.onmicrosoft.com which looks like a scam.

Eric Weinstein (@ericrweinstein) 's Twitter Profile Photo

Even light censorship works for a while. I, for example, apparently had no idea just how crazy the claims in the Hunter Biden story really are. Still trying to get my head around what I think I just saw.

benmmurphy (@benmmurphy) 's Twitter Profile Photo

An upside of the current voter fraud allegations should be more support for voting that is automatically verified by risk limited audits conducted manually using paper ballots. The good thing is some of the states in question already do this.

benmmurphy (@benmmurphy) 's Twitter Profile Photo

hash-dos review of #erlang/#elixir phash/phash2 gist.github.com/benmmurphy/8db… erlang dict/ets potential denial of service. new maps based on hash array mapped trie don't seem vulnerable

benmmurphy (@benmmurphy) 's Twitter Profile Photo

has anyone seen sites hosted behind Cloudflare return HTTP2 message of type 12 [?] which have a 16 bit length followed by the string drand.cloudflare.com . a bit spooky...

benmmurphy (@benmmurphy) 's Twitter Profile Photo

TIL: glib uses a mutex that is shared between all objects for handling signals. github.com/GNOME/glib/blo… github.com/GNOME/glib/blo…

benmmurphy (@benmmurphy) 's Twitter Profile Photo

for anyone playing around with AWS ALB MTLS. the new headers are: X-Amzn-Mtls-Clientcert w/passthru, and X-Amzn-Mtls-Clientcert-Serial-Number, X-Amzn-Mtls-Clientcert-Issuer, X-Amzn-Mtls-Clientcert-Subject, X-Amzn-Mtls-Clientcert-Validity and X-Amzn-Mtls-Clientcert-Leaf w/verify

benmmurphy (@benmmurphy) 's Twitter Profile Photo

aws ipv4 charging rant: * you want to access dynamodb streams from EC2 you will need a public ipv4 address and we will charge you for it * you can't even use private link and pay AWS the privilege of connecting to their own services.

benmmurphy (@benmmurphy) 's Twitter Profile Photo

Colorado should not be able to bar Trump from the Primaries due to being unqualified under the 14th since it is not clear that he would be unqualified at the point of assuming office even if he was guilty of insurrection. A vote by both houses can remove the disqualification.

benmmurphy (@benmmurphy) 's Twitter Profile Photo

has anyone else noticed the interesting list of naught words in /System/Library/PrivateFrameworks/DialogEngine.framework/DialogEngine > "it’s like they hired some dutch boomer to come up with the most depraved combos"

benmmurphy (@benmmurphy) 's Twitter Profile Photo

archive.ubuntu.com is on fire. this also seems to be effecting the EC2 ubuntu mirrors. I suspect they lazily cache packages so if your package is not cached the EC2 ubuntu mirrors are returning 503.

benmmurphy (@benmmurphy) 's Twitter Profile Photo

another obviously untested/unreviewed cryptographic challenge implementation. you can tell because the challenge looks like: [B@12ab34cd . why would you have the result of java bytes.toString() in your authentication protocol?

benmmurphy (@benmmurphy) 's Twitter Profile Photo

so apparently a Palestine protest group are committing serious acts of vandalism in central london but this is not being reported because: a) the victims don't want to advertise the vulnerability b) the group fucked up and the intended victim moved location